Dashboards & Visualizations

How do you use a custom field as a token for a drilldown?

fshimaya
Engager

I have a dashboard that contains a line chart. The query for this is something like:

search ....... | rex field=_raw " (ERROR|E|SEVERE) (?<method>[a-zA-Z0-9\. \-]*)[:\. ]" | timechart count by method limit=10 usenull=f useother=f

The custom field is "method". I would like a drill-down configured so that when the user clicks on either the data point on the chart or the label name, it will take the method value and add it to the query of the "Search" dashboard. So something as simple as:

search $method$

I have tried using $method$ but it literally adds "$method$" to the query. The reason I don't want to use "Auto" feature of the drilldown is that I don't want all the search arguments from the original query added to the drilldown (it's rather long and complicated). I just want the drilldown to have a simple query.

1 Solution

somesoni2
Revered Legend

After you timechart query, there is no field named "method" (instead you'll get a column for each value of field method). Try using $click.name2$ to capture name of the columns which is basically value of the field method.

http://docs.splunk.com/Documentation/Splunk/6.3.0/Viz/PanelreferenceforSimplifiedXML#Drilldown_event...

View solution in original post

somesoni2
Revered Legend

After you timechart query, there is no field named "method" (instead you'll get a column for each value of field method). Try using $click.name2$ to capture name of the columns which is basically value of the field method.

http://docs.splunk.com/Documentation/Splunk/6.3.0/Viz/PanelreferenceforSimplifiedXML#Drilldown_event...

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...